Privacy at the Crossroads: The CPSC’s Controversial Push for Massive ER Data Collection
A quiet, fundamental shift in federal surveillance is currently unfolding within the nation’s emergency rooms. The Consumer Product Safety Commission (CPSC)—an agency traditionally focused on the hazards of lawn mowers, kitchen appliances, and children’s toys—has initiated a sweeping, ambitious program to ingest millions of patient medical records.
The mandate, which has been presented to hospital executives as "required," demands the transmission of personally identifiable health information (PIHI) to a private third-party contractor, Konza Health. This initiative represents a radical departure from the agency’s historical role and has triggered a firestorm of legal, ethical, and privacy concerns among healthcare leaders and legal experts across the country.
The Scope of the Mandate: A Departure from Tradition
Historically, the CPSC has operated the National Electronic Injury Surveillance System (NEISS), a voluntary, long-standing program where hospitals report injuries related to consumer products. These reports have traditionally been de-identified, stripping away sensitive patient data to protect privacy while providing the agency with the data needed to issue recalls or warn the public about dangerous goods.
The new program, however, seeks to bypass these safeguards. According to internal documents and correspondence obtained by KFF Health News, the CPSC is demanding access to full medical records—including names, residential addresses, and specific diagnostic codes—for virtually all emergency room visits, regardless of whether a consumer product was involved.
The list of conditions targeted by this data grab is vast, encompassing over 10,000 diagnostic codes. It includes sensitive data points such as mental health crises, suicide attempts, vaccine reactions, and injuries involving factors outside the agency’s jurisdiction, such as stingray stings or encounters with illicit substances.
Chronology of the Surveillance Overhaul
The project’s inception coincides with a period of significant administrative instability at the CPSC. Following the firing of the agency’s three Democratic commissioners by the Trump administration, the agency has operated without its traditional governing board. Concurrently, internal workforce data reveals that nearly 20% of the agency’s career staff departed within the first 16 months of the new administration, creating an environment where radical policy changes have been implemented with limited internal oversight.

- Fall 2024: The CPSC signs a five-year contract with Kansas-based Konza Health, worth up to $15.9 million, to modernize its injury surveillance data infrastructure.
- Early 2025: Agency officials begin discreetly pressuring hospital executives to join the new system, describing participation in various communications as "mandatory."
- February 2026: At a toy industry trade event, acting CPSC Chairman Peter Feldman publicly signals the agency’s shift, confirming investments in "AI-enabled workflows" designed to handle massive volumes of electronic health records.
- March–April 2026: Hospitals, including Mary Greeley Medical Center in Iowa, receive formal onboarding letters. In some instances, these letters are accompanied by the notification that funding for the original, voluntary NEISS program is being terminated.
- July 2026: Following inquiries from journalists, the CPSC formally announces the program, though it omits details regarding the collection of identifiable data or the alarm raised by the hospital industry.
Supporting Data and the Role of Private Contractors
Central to this operation is Konza Health, a private organization that functions as a health data exchange. While the CPSC claims the move is a necessary "modernization" to improve surveillance, the reliance on a private entity to ingest, parse, and analyze millions of patient records has raised significant red flags regarding data security.
The CPSC’s internal manual explicitly prohibits the collection of identifiers such as birthdates or addresses, noting that such information is necessary for follow-up in less than 1% of cases. The new program ignores these limitations. When asked about the potential for data breaches, the agency has offered only verbal assurances. This is particularly concerning given the CPSC’s own track record; between 2017 and 2019, the agency was responsible for the improper release of sensitive health information belonging to approximately 30,000 individuals.
Critics argue that the involvement of a private contractor creates a "privacy black hole." Sharona Hoffman, a professor of health law at Case Western Reserve University, noted that the outsourcing of such sensitive data to a private company introduces risks that the data could be utilized for secondary purposes, such as business analytics or marketing—uses that remain a persistent fear despite the agency’s verbal claims that the data is protected.
Official Responses and Regulatory Questions
The CPSC’s aggressive approach to data collection has placed it at odds with established federal law. The Administrative Procedure Act requires agencies to provide public notice and a formal comment period before initiating new data collection efforts involving 10 or more entities. Despite plans to recruit at least 100 hospitals, the CPSC has bypassed this requirement.
Steve Roney, a spokesperson for the CPSC, acknowledged in an interview that the agency had not yet fulfilled its legal obligation to notify the public. When questioned about the lack of voluntary participation, Roney suggested that the old, opt-in system limited the "usefulness" of the data, implying that a more coercive approach was necessary.
Furthermore, CPSC officials have hinted at the potential use of "information blocking" regulations—typically used to penalize hospitals that prevent the exchange of health data—against institutions that refuse to participate in this specific surveillance program. This threat has been met with defiance by some of the nation’s most prestigious health systems. Mass General Brigham in Boston has explicitly declined to participate, citing the need to prioritize patient privacy, while others, such as Seattle’s Harborview Medical Center, have pointedly reminded the agency that they are not under any legal obligation to surrender patient data.

Implications for Healthcare and Privacy
The implications of the CPSC’s initiative extend far beyond the technicalities of injury reporting. By demanding comprehensive, identifiable records for non-product-related incidents—such as vaccine reactions or mental health conditions—the agency appears to be transforming into a broader public health monitoring body without the requisite legislative mandate or public transparency.
The Erosion of Trust
The shift from a collaborative, voluntary model to a coerced, mandatory one risks eroding the trust between the government and healthcare providers. Hospitals are the custodians of some of the most intimate data an individual possesses. If that data can be vacuumed up by an agency tasked with regulating lawn mowers, it sets a chilling precedent for the future of patient privacy in America.
The "AI" Uncertainty
The agency’s reliance on "AI-enabled workflows" and "advanced analytic parsing" adds another layer of opacity. The lack of clarity on how these algorithms function, what they deem "important," and how they filter the records of millions of Americans raises questions about the accuracy and reliability of the data being produced. As noted by former CPSC chair Alexander Hoehn-Saric, there is a fundamental lack of clarity regarding why the agency needs this level of detail. The strategy appears to be one of "collect everything," a philosophy that prioritizes data volume over patient dignity and legal safeguards.
A Regulatory Overreach
Legal experts are increasingly questioning the statutory basis for the CPSC’s demands. Federal public health authorities, such as the CDC, cannot legally mandate the reporting of private health data in this manner. For a smaller agency like the CPSC to demand such access suggests a potential overreach that may invite litigation. As more hospitals evaluate their legal exposure under HIPAA and other privacy regulations, the CPSC may find that its attempt to "modernize" has instead created a protracted legal battle that threatens the viability of the program entirely.
As the program stands, it represents a pivotal moment in the American surveillance landscape. Whether the CPSC will be allowed to continue its data grab unchecked, or whether it will be forced to retreat to its traditional, product-focused, and privacy-respecting roots, remains to be seen. For now, the nation’s emergency rooms remain the primary theater of this conflict, with the sensitive records of millions of patients hanging in the balance.